
A 2010 Worm Still Trips a Live Tofsee Fingerprint — and Now It's Hauling a Miner
A Sality-lineage dropper first seen in mid-2010 still triggers a live malicious-JA3 detection tied to Tofsee infrastructure. In the same late-September indicator set it surfaces alongside a matched XMRig mining kit and two low-detection image-disguised payloads, suggesting a fifteen-year-old worm repurposed as delivery plumbing for commodity cryptomining.
A Sality-lineage dropper that first surfaced in mid-2010 is still active enough to trip a live malicious-JA3 detection tied to Tofsee command-and-control infrastructure, and in the same indicator set it turns up alongside a matched XMRig mining kit — an executable and its configuration file staged through identical randomized-hex Temp folders — plus two low-detection payloads disguised as image files.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read